Description
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27. Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Memory Corruption
Action: Patch
AI Analysis

Impact

The vulnerability stems, mitigated by removing the vulnerable code path. An attacker can trigger it by mounting a maliciously crafted disk image, leading to unexpected system termination or corruption of kernel memory. The primary impact is loss of system availability due to crashes and potential instability of kernel memory.

Affected Systems

Apple macOS, specifically the Golden Gate release. The vulnerability was addressed in macOS Golden Gate 27; older revisions of the operating system remain affected.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5, indicating a medium severity assessment. The EPSS score is below 1%, suggesting a low probability of exploitation in the general population. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to supply a malicious disk image that the operating system mounts, which is inferred from the description and represents a local or remote abuse depending on how the image is introduced to the system.

Generated by OpenCVE AI on September 20, 2026 at 20:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to macOS Golden Gate 27 or later
  • Reboot the system after applying the update to ensure the patched kernel is active
  • Until the update is applied, avoid mounting disk images from untrusted or unknown sources

Generated by OpenCVE AI on September 20, 2026 at 20:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 20 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Kernel Memory Corruption via Malicious Disk Image on macOS

Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 16 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption in macOS via Malicious Disk Image Mounting
Weaknesses CWE-119

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Memory Corruption in macOS via Malicious Disk Image Mounting
Weaknesses CWE-119
CWE-787

Tue, 15 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27. Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T14:18:28.267Z

Reserved: 2026-09-01T21:13:17.757Z

Link: CVE-2026-84588

cve-icon Vulnrichment

Updated: 2026-09-15T14:18:22.501Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:34.887

Modified: 2026-09-16T15:27:29.370

Link: CVE-2026-84588

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:45:03Z

Weaknesses